An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
https://github.com/swagger-api/swagger-petstore/blob/master/src/main/resources/openapi.yaml
https://github.com/swagger-api/swagger-petstore
https://gist.github.com/HouqiyuA/4efd1aac7c7c7ab0cd5db48d62541a74